CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14. |
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14. |
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14. |
3Debian FedoraprojectGoogle4Debian Linux FedoraProtobuf Cpp+1 moreJun 17, 2026 Sep 22, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17....Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 22, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Use After Free in GitHub repository vim/vim prior to 9.0.0530. |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
3Debian FedoraprojectIsc3Bind Debian LinuxFedoraJun 17, 2026 Sep 21, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service. |
4Canonical DebianLinux+1 more4Debian Linux Hci Baseboard Management ControllerLinux Kernel+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 21, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release. |
3Apple DebianFedoraproject5Debian Linux FedoraIpados+2 moreJun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution. |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte ran...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded fo...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-en...Show more |
2Debian Frrouting2Debian Linux FrroutingJun 17, 2026 Sep 19, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c. |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Sep 19, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long...Show more |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Sep 19, 2022 N/A· v4 4.4 MEDIUM· v3 N/A· v2 An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for...Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 18, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Use After Free in GitHub repository vim/vim prior to 9.0.0490. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Sep 18, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. |